← Back

CVE-2026-21724

nvd nist
Published: Mar 26, 2026Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.

Affected (4)

Products: Grafana: Grafana
1 product
Grafana
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Grafana
From 11.6.9 to 11.6.14
From 12.1.5 to 12.1.10
From 12.2.2 to 12.2.8
From 12.3.1 to 12.3.6

References (1)

Source: security@grafana.com
Vendor Advisory

Timeline

No history available yet.